Touchline Analysis
Legal

Privacy Policy

Version 1.10 · Last updated 11 September 2026

This policy explains what Touchline Analysis collects, why, where it is kept, and what you can do about it. It is written for the thing that actually matters here: your match video, which is often video of children.

The short version

This summary is here so you actually read something. Where it and the detail below disagree, the detail below is what governs.

1. Who we are

Touchline Analysis is operated by Dhruv Jain, Sole Proprietor, trading as Touchline Analysis — a sole proprietorship registered in India at C-1505 Ashok Towers, Dr S S Rao Road, Parel, Mumbai 400012, Maharashtra, India. In this policy “we”, “us” and “our” mean that entity, and “you” means the person using the app.

One address reaches us for everything: [email protected]. Putting [PRIVACY] at the start of the subject line is not a requirement — a plain email is answered the same — it only sorts your message to the right place faster. The links on this page fill it in for you.

2. What we collect

2.1 What you tell us when you register

WhatWhy we need it
Your nameTo address you in the app and to show teammates who tagged or shared a match.
Your email addressIt is your login, and the address a club roster files your place under. You can sign in with a Google account, with a password, or with a one-time link sent to this address. Passwords are handled by Google Firebase Authentication and stored hashed by them — we never see or hold one.
Club or team nameTo group matches and to name the shared workspace your teammates join.
SportTo set up sensible tag panels for what you actually play.
Age groups (youth, women’s or men’s — any combination)To know whether the footage you are about to store is of children, which changes our obligations and yours. See §6.
A mobile numberSo we can reach you about your account when email does not work — a failed sign-in, a problem with your footage, or the end of your free period. We do not use it for marketing and we do not pass it to anyone.
A contact email, if you are setting up a clubThe address we should write to about the club, which may not be the address you sign in with — a club administrator often sets the account up for a coach. It defaults to your sign-in address.
How many players and coaches you have, if you are setting up a clubTwo approximate numbers, so we can tell you which plan fits and can size the account correctly. They are not names and not a roster; nothing in the app is limited by them.

We do not ask for your date of birth or your postal address. Data we do not hold cannot be lost, leaked, or demanded from us.

If you are joining a club that already exists, you are asked for your name only. Everything else in this table was answered by whoever set the club up.

2.2 What the app creates as you use it

2.2a The download log — a record of who took what

This is new, and it records behaviour rather than content, so it is written out in its own section rather than buried in the list above.

When a club’s footage is opened from the cloud, or when anyone in a club saves a file out of the app, we write one row to that club’s own records. Each row holds five things and nothing else: the email address of the person, what it concerned (the match or presentation, by its identifier or its name), when, which route it took — match footage, a whole reel, a single clip, or an export such as a tags CSV, a report or a backup file — and, for cloud footage, how large the file was. It does not record what you watched, which part you watched, how long for, how many times you pressed play, your IP address, or your location.

Why we hold it. This service carries footage of matches, often including children. If a club ever needs to establish who took a copy of a game out of the app, there has to be an answer. Without a record, the honest reply to “who downloaded this” is “nobody can tell”, and for footage of children that is not an acceptable answer.

Who can see it. Your club, and only your club — the rows live inside your club’s own data alongside your matches, and every member of your club can read them. We do not build cross-club reports from them, we do not analyse them, and they are never used for advertising, profiling or ranking anybody. If you are a player, you can see that footage you appear in was taken a copy of, and by whom.

Nobody can edit or delete a row, including us and including your club owner. That is enforced by the database itself, not by a policy we promise to follow: rows can be created and after that they cannot be changed or removed by anyone signed in to the app. A log the person with most to hide can quietly correct is not worth having. The consequence is that rows outlive the thing they describe — deleting a match does not delete the record that somebody downloaded it — and the only thing that removes them is deleting the whole club, which erases them with everything else. §7 gives the retention period.

One limit, stated plainly rather than glossed. The row for cloud footage is written by our own servers at the moment access is granted, so it cannot be avoided. The rows for reels, clips and exports are written by the app on the device, which means somebody who deliberately modified the app on their own computer could avoid writing one. We will not describe those rows to you or to anybody else as tamper-proof, because they are not. They are an accurate record of ordinary use.

2.3 What we do not collect, and what we do measure

NameWhat it is forHow long it lasts
fi_didHolds the random device identifier so the website and the app recognise one device as one device. Nothing else reads it and nothing else is stored in it.400 days, or until you clear your browser’s storage
__Secure-fi_vbSet only when you open a match video from the cloud. It holds your signed account identifier and nothing else, is sent only to the video address on this site, and cannot be read by any script — including ours. It is what ties a video link to you, so that a link copied out of the page does not work for anyone else.One hour, matching the video link it goes with

If that posture ever changes — if we ever need a cookie that is not strictly necessary — this policy changes first and you will be asked to consent before it is set.

3. Your match video — the part that matters

Video is the most sensitive thing this service touches, so it gets its own commitments.

Hosted video is open, and the commitments below are live. A match reaches us only when someone in your club chooses to share it; everything else stays in your own device’s storage and is not uploaded.

The honest caveat, because a policy that pretends otherwise is worthless: an operator with administrative access to any storage system can technically reach the files it holds. What we commit to is that doing so is not part of how the service runs, is restricted to named administrators, and would only ever happen to investigate a specific fault you have reported to us or to comply with a legal order.

4. Where your data is kept

Structured match data (tags, presentations, account details) and match video are held with the infrastructure providers listed in §9. Structured match data is stored in asia-south1 (Mumbai, India), which is a contractual region: our provider commits to keeping it there. Match video is stored with Cloudflare R2 in the Asia-Pacific region.

Those two sentences look alike and are not, so we would rather spell out the difference than let it read as one promise. R2 accepts a regional hint when a bucket is created and honours it on a best-effort basis. Asia-Pacific is therefore a placement preference, not a guaranteed location, and not a data-residency commitment. We deliberately do not name a country for footage, because we could not stand behind it if we did.

Footage stays on your device unless someone in your club shares a match. When they do, a copy is held in R2 under your club’s control, and your club can delete that copy at any time (§7). Your device remains the primary copy of anything you have not uploaded. The app is built to work with no network at all, which means it is normal and expected for us to hold nothing about a match you have recorded.

We process your data on these bases:

6. Footage of children

Most youth sport analysis is footage of under-18s. We treat this as the highest-risk thing on the platform, and the law agrees: under §9 of the Digital Personal Data Protection Act 2023, a child’s personal data may be processed only with verifiable consent from a parent or lawful guardian, and tracking, behavioural monitoring and targeted advertising directed at children are prohibited outright. There is no legitimate-interest route around it.

7. How long we keep it

DataKept for
Matches and presentations you delete10 days in the app’s recycle bin, on every plan, so a mistake is recoverable. Then permanently erased. You can empty the bin yourself at any time to erase them immediately.
Match video you deleteVideo you have not shared is held on your own device, so deleting it removes it there, recoverable from the recycle bin for the same 10 days. The cloud copy of a shared match is different, and we would rather say so plainly: when your club deletes it, it is erased from our video storage straight away and cannot be recovered. There is no 10-day window for it, no copy in a backup, and nothing that ages out on a timer — the object is gone. A multi-gigabyte file is not something we keep after you have asked us not to, and the app asks for a heavier confirmation because of it. One limit, because it is true: somebody already watching that match when it is deleted can finish the part their player had already loaded, and no new viewing of it can be started by anyone, including them.
The download log (§2.2a)For as long as the club exists. Rows are deliberately permanent and uneditable — nobody, including us and including your club owner, can alter or remove one, which is the only thing that makes the record worth anything in a dispute. They therefore outlive the match they describe: deleting a match, or emptying the recycle bin, does not delete the record that somebody downloaded it. Deleting the club erases them along with everything else it holds.
BackupsUp to 7 days. Deleted data can survive in a backup for this window before ageing out. This is how a restore is possible at all.
Enquiry and sign-up details24 months from the last time we were in contact with you, then the record is deleted. This covers what you typed into the contact form on our website and the registration details that reach us when a club signs up (§2.1). If you ask us to delete it sooner we will — email [email protected] and it goes within 30 days. The clock restarts on contact, not on the first message, so an ongoing conversation is never cut off mid-way.
Your account, if you close itErased within 30 days, excluding records we must keep by law (below).
Billing and tax recordsAs long as tax law requires — typically 6 years from the end of the financial year they relate to. These contain invoice and payment details, not footage.
What happens if you stop payingYour plan runs to the end of the period you paid for. Then 10 days in which you can sign in and download everything held in the cloud, but not upload. After that, everything we hold in the cloud — footage, matches, tags, presentations — is permanently deleted and cannot be recovered. Anything on your own device is untouched. Full detail in the Refunds & Cancellation Policy §4.

8. Your rights, and how to use them

Two of these are buttons in the app, not requests you have to make to us:

Depending on where you live, you also have the right to access, correct, or erase your data, to object to or restrict processing, to data portability, to withdraw consent, and to complain to your data-protection authority. Email [email protected] and we will respond within 30 days. We do not charge for this.

9. Who else touches your data

Every company that can touch data belonging to you or your club, what each one does, and where it holds it. This is the list a school’s data protection officer asks for, so it is published here and kept current rather than sent on request. They process data on our instructions only, and none of them may use it for their own purposes.

On the Basic plan most of this does not apply to you — footage never leaves your device, so no provider below holds it, and neither do we.

ProviderWhat forWhat it sees
CloudflareServing the website and the appStandard request data (IP address, page requested) needed to deliver a web page
Cloudflare Web AnalyticsCounting page views and load speedThe page requested, the page that referred you, and coarse device and country information. No cookie, and no identifier that could follow you across sites.
SentryCollecting JavaScript errors so faults get fixedThe error message, the stack trace, and the page URL the error happened on. Personal-data collection is switched off (sendDefaultPii: false), so your IP address, request headers and cookies are not attached. The honest residual: an error message can quote text that was on screen, and in this app that can include a match title, a club name or a player name.
Web3FormsDelivering the contact form on our website to our inbox, and telling us when a new club signs up in the appFor the contact form: the name, email, message and other fields you typed into it. For a new sign-up: the registration details listed in §2.1 — your name, club, sport, age groups, mobile number, contact email and the two headcounts — and the plan you chose. In both cases, the IP address that submitted it. No match data, no tags and no video is ever sent to them.
Google (Firebase)Sign-in and the sync of tags, presentations and account detailsYour email address, account details, and match tag data — not video
Google (Gmail and Sheets)Receiving mail sent to us, and keeping one row per enquiry so we can answer it and know who askedThe same contact-form and sign-up details Web3Forms delivers, kept as a record rather than only as an email. Retention is in §7. No match data, no tags and no video.
Cloudflare R2Storing and delivering uploaded match footageThe video files for matches your club has chosen to share, encrypted at rest. They are delivered only through signed, per-request links scoped to a single match, tied to the account they were issued to, and valid for one hour — never a public URL. Footage nobody has shared is never sent here.
Cashfree PaymentsTaking paymentYour billing details — your name, your email address and the amount. We never see or store your card number: it is entered on Cashfree’s own page and held by them, as RBI rules require.
YouTube (only if you choose it)Playing back a match you have hosted on YouTube yourselfOnly what YouTube already sees. We embed the privacy-enhanced player, so nothing is set unless you press play.

9.1 The legal entities, and where each one holds it

The same list again, named the way a procurement form needs it.

EntityRoleWhere it holds it
Cloudflare, Inc.Serves the website and the app; DNS and TLS; cookieless visit counts; stores and delivers uploaded match video (R2); routes mail addressed to hello@ onward to our inboxGlobal edge network; video in the Asia-Pacific region — a placement preference rather than a residency guarantee, see §4
Google LLC (Firebase, Gmail, Sheets)Sign-in links, the accounts database, and team sync of matches, tags and presentations; also our own mailbox, and the sheet that records enquiriesFirebase in asia-south1 (Mumbai, India). The mailbox and the enquiry record sit on Google's general infrastructure and are not region-pinned — §10 covers what that means.
Functional Software, Inc. (Sentry)Error reportingUnited States
Web3FormsDelivers the website contact form and the new-sign-up notification from the appUnited States
Cashfree Payments India Private LimitedTakes payments and issues receiptsIndia

Both locations above are fixed when the project or the storage bucket is created and cannot be moved afterwards, so each is a decision rather than a default. They are not the same kind of statement: asia-south1 is a contractual region, while the Asia-Pacific placement of the video storage is a best-effort preference. §4 explains why we do not flatten the two.

9.2 Where your footage actually lives

Worth separating out, because it is the question that matters most and the answer changes with your plan:

9.3 Who is responsible for what

The Digital Personal Data Protection Act 2023 calls these roles Data Fiduciary (the one who decides) and Data Processor (the one who acts on instructions). It would be convenient for us to claim we are only ever the second. We are not, and saying so would not survive contact with the facts:

What this means in practice, and it is the reason the distinction is worth the paragraph: a parent, a player or a coach can bring a request to us and we will act on it ourselves. We will not send you back to your club and call that an answer.

The companies in the table above are our sub-processors — they act on our instructions, on the same terms, and may not use anything they hold for their own purposes.

9.4 Changes to this list

We keep this list current: a provider added to the product is added here in the same release. For a new provider that can access footage or personal data, we publish the change at least 30 days before it takes effect, so a club with a procurement process has time to object. If you object and we can’t resolve it, you can cancel before the change takes effect, and your plan runs on to the end of the period you have paid for — the new provider is never introduced into a period you bought without it. To be told about changes, email [email protected] and ask to be added to the notice list. It is used for nothing else.

10. International transfers

Some of what we hold is processed outside India, so this section names which parts and what protects them. It is short because the honest answer is short.

11. Security

Said plainly enough that a school’s IT contact can check it. Every control here exists today — we would rather leave a line out than describe one we are still building.

11.1 Accounts and sign-in

11.2 Your data

11.3 How the app is built

11.4 Reporting a vulnerability

Email [email protected] with [SECURITY] in the subject. Our machine-readable contact is at /.well-known/security.txt. Please include what you found, the steps to reproduce it, and what an attacker could achieve; a working proof of concept is welcome, a screenshot of a scanner’s output usually isn’t enough to act on.

What we commit to: an acknowledgement within 3 working days, an honest assessment of what we think it is and what we intend to do, credit here if you’d like it once the fix is out, and we will not pursue legal action against you for research that follows the rules below. We deliberately do not publish a fix deadline: we are one person, the right timeline depends on what you found, and we would rather agree a real date with you than miss a printed one.

What we ask: use your own account and your own test data — don’t access, modify or keep anyone else’s footage, because this platform holds video of children and that line is not negotiable. No denial of service, no spam, no social engineering. Give us reasonable time to fix it before publishing, and stop as soon as you’ve proved the issue: reading one record to confirm access is a proof, downloading a database is not.

We don’t run a paid bug bounty. We’re honest about that up front rather than leaving it to be discovered after the work is done.

11.5 If something does go wrong

We’ll tell you. Where a breach affects your personal data we notify affected users and the Data Protection Board of India as the law requires, and we tell you what was affected and what to do about it. Our understanding of an incident may be incomplete, but it won’t be shaded.

If you need documentation for a procurement or safeguarding review — an information security policy, a data processing agreement, or this list in a signable form — ask at [email protected].

12. Changes to this policy

If we change this policy in a way that materially affects you, we will say so in the app before the change takes effect. The version number and date at the top always tell you which version you are reading.

13. Contact

There is one address, and it is read by the people who build this: [email protected]. A subject tag helps it reach the right place faster, and every link on our pages fills one in for you — but an untagged email is never turned away.

Subject tagUse it forFirst response
[SAFEGUARDING]A child’s safety, or footage that should not exist. See Report Content.Ahead of everything else. Acknowledged within 24 hours
[GRIEVANCE]A formal complaint (Grievance Officer, §13.1)72 hours — or 24 hours where it concerns a child — resolved in 15 days
[REPORT]Other content that shouldn’t be on the platform3 working days
[PRIVACY]Access, correction or erasure of your data3 working days, resolved within 30 days
[SECURITY]A vulnerability (§11.4)3 working days
[BILLING]Payments, invoices, plans, cancelling3 working days
[SUPPORT]Everything else3 working days

13.1 Grievance Officer

If something about this service has gone wrong for you — your data, your account, your money, or how we have behaved — this route gets you a named person and a written answer within a stated time.

Name
Dhruv Jain
Designation
Grievance Officer & Data Protection contact
Email
[email protected] — subject [GRIEVANCE]
Phone
+91 80800 90005 — Mon–Fri, 10:00–18:00 IST
Post
The registered address below, marked for the Grievance Officer

What this route is for: your personal data (a copy, a correction, or erasure — tag those [PRIVACY]); content about you that should not be on the platform; an account you have lost access to; a charge you do not recognise; or a decision you think we got wrong. If it involves a child’s safety, use Report Content instead — that route is separated from ordinary mail and dealt with ahead of it.

What to include, so the first reply is the useful one: the email address on the account (that is how we find you), your club or team name if the complaint concerns team data, what happened and when, and what you would like us to do. Please do not attach footage. Tell us where it is in the app and we will find it — sending it makes an extra copy of exactly the material you may be asking us to delete.

  1. Within 72 hours — acknowledged. Within 24 hours if it concerns a child. In writing, with a reference and the name of the person handling it. Weekends included. Three days is what one person can honestly hold for a billing dispute or a data request. It is not what a complaint about a child’s footage deserves, so that one keeps the 24-hour window and is acknowledged ahead of everything else — tag it [SAFEGUARDING], or use Report Content, which needs no account and asks the questions we actually need in order to act.
  2. We investigate We may come back with questions. Where we need to look at account records to answer you, we look at the minimum that answers it, and we log that we did.
  3. Within 15 days — resolved A written decision: what we found, what we have done, and what we have not done and why. If something genuinely cannot be finished in 15 days, you get the reason and a date before the 15 days are up, not after.

Most data requests do not need us at all. Settings ▸ Download my data exports everything the app holds, and Settings ▸ Delete my account erases it. This route is for what those two buttons cannot do.

You do not need to go through your club, and we will not send you there instead of answering. For footage of players your club is a Data Fiduciary and so are we (§9.3), which means a request that reaches us is ours to act on. In practice: we act on it, we tell the club we have, and where the decision is genuinely the club’s to make — whether a match stays up at all — we say so, give you our own answer alongside theirs, and tell you what to do if you disagree with it. A parent or guardian who has no account here has the same route as anyone else. See §6.

If we do not fix it, our answer is not the end of the road and we will not pretend otherwise: the Data Protection Board of India for personal data under the DPDP Act 2023; the National Consumer Helpline (1915) or your District Consumer Disputes Redressal Commission for a service or billing complaint; cybercrime.gov.in or your local police for anything criminal — please also tell us, so we can preserve what is relevant.

Touchline Analysis (sole proprietor: Dhruv Jain), C-1505 Ashok Towers, Dr S S Rao Road, Parel, Mumbai 400012, Maharashtra, India. +91 80800 90005